Vulnerability Description
On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elspec-Ltd | G5Dfr Firmware | < 1.2.3.13 |
| Elspec-Ltd | G5Dfr | - |
Related Weaknesses (CWE)
References
- https://www.elspec-ltd.com/metering-protection/g5-multi-functional-digital-faultProduct
- https://www.elspec-ltd.com/support/security-advisories/Vendor Advisory
FAQ
What is CVE-2025-59392?
CVE-2025-59392 is a vulnerability with a CVSS score of 6.8 (MEDIUM). On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port...
How severe is CVE-2025-59392?
CVE-2025-59392 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59392?
Check the references section above for vendor advisories and patch information. Affected products include: Elspec-Ltd G5Dfr Firmware, Elspec-Ltd G5Dfr.